VYPR

Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings

by WordPress

CVEs (12)

  • CVE-2026-19796HigSep 1, 2026
    risk 0.47cvss 7.2epss 0.00

    The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter in all versions up to, and including, 5.8.1 due to insufficient input sanitization and output escaping.…

  • CVE-2025-1570HigFeb 28, 2025
    risk 0.46cvss 8.1epss 0.00

    The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_generate_password_reset_pin_code() and…

  • CVE-2026-84150MedSep 23, 2026
    risk 0.35cvss 5.4epss 0.00

    The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches the authenticated caller before reading and modifying that user's saved favorites, allowing any authenticated user…

  • CVE-2026-77757MedAug 26, 2026
    risk 0.35cvss 5.4epss 0.00

    The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does not sanitize a user-supplied image reference before using it as the source of a file move, allowing users with a subscriber-level account to relocate arbitrary…

  • CVE-2025-12174MedNov 19, 2025
    risk 0.35cvss 6.5epss 0.00

    The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'directorist_prepare_listings_export_file' and 'directorist_type_slug_change' AJAX actions in all…

  • CVE-2026-84026MedSep 23, 2026
    risk 0.34cvss 5.3epss 0.00

    The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, allowing unauthenticated attackers to read registered users' private contact details.

  • CVE-2026-84046MedSep 23, 2026
    risk 0.33cvss 5.0epss 0.00

    The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the subscriber role and above to make the server issue requests to internal addresses.

  • CVE-2026-84027MedSep 23, 2026
    risk 0.28cvss 4.3epss 0.00

    The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with…

  • CVE-2025-2224MedMar 25, 2025
    risk 0.27cvss 5.3epss 0.00

    The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This…

  • CVE-2024-12041MedFeb 1, 2025
    risk 0.27cvss 5.3epss 0.00

    The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for…

  • CVE-2025-12953MedNov 11, 2025
    risk 0.21cvss 4.3epss 0.00

    The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the "rtcl_ajax_add_listing_type", "rtcl_ajax_update_listing_type", and…

  • CVE-2026-84066LowSep 4, 2026
    risk 0.20cvss 3.1epss 0.00

    The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above…